Lab 1.2 : Consuming Threat Intelligence
Objectives
- Practice the methodology of leveraging Threat Intelligence for Red Team Engagements
- Understand the Target Organization
- Identify the Adversary
- Gather Threat Intelligence
- Extract TTPs
- Analyze and Organize
- Create an Adversary Emulation Plan
Lab Preparation
Please ensure you are connected to the Internet by following Lab 0.
Ensure you are connected to the internet by pinging sans.org from your host system. Open a command prompt or terminal window and type:
ping -c 4 sans.org
Walkthrough
Methodology Overview
We will follow the methodology introduced in courseware for this lab:

The above methodology for leveraging threat intelligence for Red Team engagements was inspired by Katie Nickels and Cody Thomas presentation during the SANS Threat Hunting & Incident Response Summit presentation on September 6, 2018 titled: ATT&CKing the Status Quo: Threat Based Adversary Emulation with MITRE ATT&CK™.
Understand the Target Organization
Threat Intelligence providers and internal teams must understand the organization, industry, and specific threat landscape of the country it operates in. The Red Team will need to understand the attack surface of the target organization. The objective is to form a detailed picture of the target and its weak points from the attacker's perspective. The output of this activity is the identification of the attack surfaces of people, processes, and technologies relating to the organization and its global digital footprint.
The target organization for the course is Draconem Development. This is a fictitious company created for SANS Security 565. For this lab we will look at some background information on our Target and also Cyber Threat Intelligence (CTI) reports on our emulated adversary group.
As the Red Team for Draconem Development, we've identified a state-sponsored cyber espionage group as a potential adversary. The software company is focused on artificial intelligence (AI). Their main offering is an AI driven medical research product and in recent years they shifted their development to focus on infectious diseases. This shift highlighted them as a target of our adversary. The goal of the engagement is for your team to emulate the adversary group to ensure the Blue Team has the proper detection and response in place.
Identify the Adversary
1. Navigate to MITRE ATT&CK™ site:
Search on the top right for keywords identified from what you learned from the target organization:
artificial intelligence
medical research
infectious disease
Warning
The MITRE ATT&CK™ search bar is VERY slow, wait for it to populate.

Which groups came up for those searches?
Magic Hound and HAFNIUM may have come up due to the types of organizations that they target. Our chosen threat actor will be HAFNIUM
Gather Threat Intelligence
2. Navigate to /labs/sec-1/threat-intel on the SlingShot Linux VM. The course materials contain reports on the adversary you will be emulating in this class.
Threat Intelligence contains a lot of information about the adversary, their objectives, attribution, Indicators of Compromise (IoCs), and Tactics, Techniques, and Procedures (TTPs). Consuming threat intelligence will require reviewing all the information and extracting what will be relevant for the adversary emulation engagement.
The Red Team is interested in the top of David Bianco’s Pyramid of Pain. Blue Teams are usually lower on the pyramid as they mature their detection capability. Those Indicators of Compromise such as hash values, IP Addresses, and Domain Names will not be very useful for the Red Team. The Red Team will want to focus on TTPs and Tools. This is also what Hunt Teams focus on as well. The Red Team will need to be flexible as the Pyramid of Pain works both ways; it is tough and challenging for Red Team (or adversary) to change TTPs and Tools during normal operations.

Reference: https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html
Read different sources of Threat Intelligence
3. Skim the three reports that are located in the threat-intel folder on the course media.
- Microsoft-HAFNIUM-report.pdf
- Mandiant-Microsoft-Exchange-Zero-Days.pdf
- Volexity-Operation-Exchange-Marauder.pdf
The original sources are:
- https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
- https://www.mandiant.com/resources/detection-response-to-exploitation-of-microsoft-exchange-zero-day-vulnerabilities
- https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/
Extract TTPs
In this step, you will extract TTPs from the Threat Intelligence acquired and map it to a framework like MITRE ATT&CK™, the industry standard to identify and document common TTPs of adversaries.
Tactics, Techniques, and Procedures are often abbreviated as TTPs and clustered together as one thing: "The adversary's TTPs". However, they represent three different aspects of adversary activity at different levels of abstraction.
-
Tactics are high-level methods to achieve a goal.
-
Techniques are one step down that refer to how that goal will be achieved.
-
Procedures are the granular step that describes the steps taken in achieving the goal.
The below example is derived from three threat intelligence sources you will read. It shows mapping to TTPs and highlights tools used in green. The Red Team is most interested in Tools and TTPs. The tools used may give the Red Team more TTPs for the assessment.

4. Skim through the Threat Intelligence again and highlight the TTPs and Tools like the above example.
Analyze & Organize
Creating an Adversary profile is a great way of establishing a high level plan for how the Red Team will execute testing. The goal is to have a simple table to show what the Red Team will emulate.
5. Think about what information you would add to a snapshot view of this threat actor based on the threat intelligence.
6. Categorizing the information below into a table describing the threat actor.
Highlights related to HAFNIUM profile:
HAFNIUM primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs.
HAFNIUM has previously compromised victims by exploiting vulnerabilities in internet-facing servers, and has used legitimate open-source frameworks, like Covenant, for command and control. Once they've gained access to a victim network, HAFNIUM typically exfiltrates data to file sharing sites like MEGA.
In campaigns unrelated to these vulnerabilities, Microsoft has observed HAFNIUM interacting with victim Office 365 tenants. While they are often unsuccessful in compromising customer accounts, this reconnaissance activity helps the adversary identify more details about their targets’ environments.
HAFNIUM operates primarily from leased virtual private servers (VPS) in the United States.
The following table will be filled in by the end of this lab:
| Category | Description |
|---|---|
| Description | |
| Goal and Intent | |
| Reconnaissance | |
| Resource Development | |
| Initial Access | |
| Execution | |
| Persistence | |
| Defense Evasion | |
| Credential Access | |
| Collection | |
| Command and Control | |
| Exfiltration |
Use MITRE ATT&CK™ Navigator to filter TTPs for the selected adversary
MITRE has developed the ATT&CK™ Navigator, a web application that represents the MITRE ATT&CK™ techniques in a dynamic fashion. It can be used to select specific techniques based on a threat group (e.g. select all APT-3 techniques), afterwards modifications and annotations can be made. It may have TTPs assigned to an adversary that was not provided in the Threat Intelligence. Note that the techniques for Groups/Software in Navigator are fully referenced to open sources on MITRE ATT&CK™ Groups and Software pages. Navigator is open-source and can be self-hosted!
7. Review the HAFNIUM group page on MITRE ATT&CK™ page:
https://attack.mitre.org/groups/G0125/
8. Navigate to the hosted site MITRE ATT&CK™ Navigator instance:
https://mitre-attack.github.io/attack-navigator/enterprise/
9. Click Create New Layer and then select Enterprise:

10. A MITRE ATT&CK™ Matrix will show up. Click the second icon from the left under selection controls titled search & multi-select
. Then click on Threat Groups(##) to expand the search:

11. Scroll down on the Threat Groups (##) section until you see HAFNIUM, then Click select next to HAFNIUM then click Close:

The TTPs tagged to HAFNIUM will now have a black border around it.
12. Select the second icon from left under technique controls and choose a color
.
The TTPs for HAFNIUM will now change colors.

13. You can expand the techniques to view sub techniques by clicking the ninth icon from the left under layer controls
.

14. Click the second, third, or forth icon from left under layer controls to export in JSON, Excel, or SVG respectively.

15. Continue to toggle various controls to see what they do. Pay particular attention to the technique controls where a score and comments can be added for each TTP that is selected. This may be helpful for reporting improvements as Red Team performs more and more engagements.
MITRE ATT&CK™ Navigator does a great job visualizing TTPs for a known adversary that is documented in the framework, but it does not analyze and organize the threat intelligence into a technical flow that the Red Team will be able to follow. Adversary emulation is a core aspect that distinguishes Red Team engagements from other types of security assessments. Let's take identified TTPs and fill in our threat profile table describing the Hafnium threat group.
Complete Threat Profile Table
16. Below is a threat profile table that we will expand into a more detailed plan. Below is an example. There is no "right" or "wrong". The Red Team can be flexible as long as the adversary is being emulated and the focus continues to be on the goals and objectives. Only one TTP has been filled in per category, please create your own document and fill in the rest of the identified TTPs
Threat Profile Table:
| Category | Description |
|---|---|
| Description | HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. |
| Goal and Intent | HAFNIUM primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. |
| Reconnaissance | T1592.004 - HAFNIUM has interacted with Office 365 tenants to gather details regarding target's environments. |
| Reconnaissance | TXXXX.XXX - |
| Reconnaissance | TXXXX.XXX - |
| Reconnaissance | TXXXX.XXX - |
| Resource Development | T1583.003 - HAFNIUM has operated from leased virtual private servers (VPS) in the United States. |
| Resource Development | TXXXX.XXX - |
| Initial Access | T1078.003 - HAFNIUM has used the NT AUTHORITY\SYSTEM account to create files on Exchange servers. |
| Initial Access | TXXXX.XXX - |
| Execution | T1059.001 - HAFNIUM has used the Exchange Power Shell module Set-OabVirtualDirectoryPowerShell to export mailbox data. |
| Execution | TXXXX.XXX - |
| Persistence | T1136.002 - HAFNIUM has created and granted privileges to domain accounts. |
| Persistence | TXXXX.XXX - |
| Defense Evasion | T1218.011 - HAFNIUM has used rundll32 to load malicious DLLs. |
| Credential Access | T1003.001 - HAFNIUM has used procdump to dump the LSASS process memory. |
| Defense Evasion | TXXXX.XXX - |
| Collection | T1560.001 - HAFNIUM has used 7-Zip and WinRAR to compress stolen files for exfiltration. |
| Collection | TXXXX.XXX - |
| Command and Control | T1071.001 - HAFNIUM has used open-source C2 frameworks, including Covenant. |
| Command and Control | TXXXX.XXX - |
| Command and Control | TXXXX.XXX - |
| Command and Control | TXXXX.XXX - |
| Exfiltration | T1567.002 - HAFNIUM has exfiltrated data to file sharing sites, including MEGA. |
Create an Adversary Emulation Plan
Tactics and Techniques have been identified, analyzed, and organized in the chart above. The final preparation for the Red Team is to create the Adversary Emulation Plan. As that portion has not been covered in the course thus far (but will be), we will review the plans for APT3 as provided by MITRE.
17. Navigate to /labs/sec-1/threat-intel on the SlingShot Linux VM. The course materials contain reports on the adversary you will be emulating in this class.
18. Open and Review the APT3_Adversary_Emulation_Field_Manual.xlsx
19. Open and Review the APT3_Adversary_Emulation_Plan.pdf
Conclusion
This lab followed the methodology of Threat Intelligence for Red Team Engagements to understand the target organization; identify an adversary; gather threat intelligence for that adversary; read different sources of threat intelligence for that adversary; Identify and Extract Tactics, Techniques, and Procedures (TTPs) used by the adversary; Create an Adversary Profile; Use MITRE ATT&CK™ Navigator to filter TTPs for selected adversary and fill in the gaps; Analyze and Organize the threat intelligence into a technical flow; and read an example of an Adversary Emulation Plan.
This is a good introduction and example of what a Threat Intelligence Analyst, Project Manager, Trusted Agents, and Red Team members will receive during the Threat Intelligence phase of an Adversary Emulation Red Team Engagement. For a good reference for Threat Intelligence based on MITRE ATT&CK™, read this blog post: https://medium.com/mitre-attack/getting-started-with-attack-cti-4eb205be4b2f
The work done in this lab will be referenced again in the course.